Mitigating opaque trigger alerts of black-box ML models with Explainable Artificial Intelligence (XAI) in Zero Trust Architectures (ZTA)
Contributors
Madhuri Rao
Ganesh Khekare
Keywords
Proceeding
Track
Engineering and Sciences
License
Copyright (c) 2026 Sustainable Global Societies Initiative

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Abstract
Zero Trust Architecture (ZTA) is based on the concept of never trusting and always verifying. Even with continuous verification and strong authentication with access control mechanisms, data breaches are yet possible. Hence Intrusion Detection Systems (IDS) are essential in ZTA. Modern IDS incorporated with Machine Learning (ML) models can detect anomalies and can also identify novel attack patterns. They are critical for cloud native environments and or application with microservice architecture. ML based IDS systems can trigger alerts and can adapt to evolving threats. Complex ML models such as XGBoost and Voting ensemble methods are even more challenging to comprehend and cause operator distrust. Such black box models could also trigger alerts without any understandable cause. Here, opaque and false trigger alerts are addressed with the help of Explainable Artificial Intelligence (XAI) SHapley Additive exPlanations (SHAP) model.